Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 251

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
United Airlines slashes 2026 forecast as fuel costs surge
Amazon launches GLP-1 weight loss program, promising 'fast, convenient' access
Bike horn for warning oblivious pedestrians
Did this crow poop on me deliberately?
Trump extends ceasefire in Iran, citing 'seriously fractured' Iranian government
Movie: The Mosquito Coast
European stocks set to open lower as Trump refuses to lift Strait of Hormuz blockade
CEO with over $3 trillion under management tells Gen-Z to think past ‘hobby investing’
Apple incoming CEO John Ternus faces a defining challenge: Fixing the company's AI strategy
Trump says 'I'll remember' companies that don’t seek tariff refunds